Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Document
Library
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiProxy
NOC & SOC Management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
/
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
/
FortiVoice Cloud
FortiRecorder
/
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
Flex-VM
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
/
FortiWeb Cloud
FortiADC
/
FortiGSLB
SAAS Security
FortiMail
/
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiInsight
/
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
/
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Curated links by solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Define, Design, Deploy, Demo
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Next Generation Firewall
Hardware Guides
Filter Products
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAI
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiEdge
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
Filter Products
AscenLink
AV Engine
AWS Firewall Rules
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiBalancer
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDNS
FortiEDR
FortiExplorer
FortiExplorer Go
FortiExtender
FortiExtender Cloud
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGSLB
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR Cloud
FortiNDR Private Cloud
FortiNDR Public Cloud
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScan
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Search documents and hardware ...
Version:
6.5.3
6.5.2
6.5.1
Version:
6.5.0
6.4.8
6.4.7
Version:
6.4.6
6.4.5
6.4.4
Version:
6.4.3
6.4.2
6.4.1
Version:
6.4.0
6.3.4
6.3.3
Version:
6.3.2
6.3.1
6.3.0
Version:
6.2.2
6.2.1
6.2.0
Version:
6.1.3
6.1.2
6.1.1
Version:
6.1.0
6.0.8
6.0.7
Version:
6.0.6
6.0.5
6.0.4
Version:
6.0.3
6.0.2
6.0.1
Version:
6.0.0
5.5.0
5.4.0
Version:
5.3.0
5.2.0
5.1.0
Version:
5.0.0
4.3.0
4.2.1
Version:
4.2.0
Table of Contents
What's new in FortiAuthenticator
FortiAuthenticator 6.4.4
FortiAuthenticator 6.4.3
FortiAuthenticator 6.4.2
FortiAuthenticator 6.4.1
FortiAuthenticator 6.4.0
Introduction
Before you begin
How this guide is organized
Registering your Fortinet product
Setup
Initial setup
FortiAuthenticator-VM setup on VMware
Administrative access
Adding FortiAuthenticator to your network
Maintenance
Backing up the configuration
Upgrading the firmware
Licensing
Swapping hard disks
Platform migration
CLI commands
Troubleshooting
FortiAuthenticator settings
FortiGate settings
System
Dashboard
Customizing the dashboard
System information widget
System resources widget
Authentication activity widget
User inventory widget
License information widget
Disk monitor widget
Top user lockouts widget
User lookup
Power supply monitor widget
Network
Interfaces
DNS
Static routing
Zero trust tunnels
Configuring a zero trust tunnel example
Packet capture
Administration
System access
High availability
Firmware upgrade
Configuring auto-backup
SNMP
Features
Licensing
FortiGuard
FortiNACs
FTP servers
Admin profiles
NetHSMs
Replacement messages
Messaging
SMTP servers
Email services
SMS gateways
Authentication
What to configure
Password-based authentication
Two-factor authentication
Two-factor token and password concatenation
Authentication servers
RADIUS
Built-in LDAP
Remote LDAP
Authentication methods
Machine authentication
User account policies
General
PCI DSS 3.2 two-factor authentication
Lockouts
Passwords
Custom user fields
Tokens
User management
Administrators
Local users
Remote users
Remote user sync rules
Guest users
User groups
Usage profile
Realms
FortiTokens
MAC devices
Identity and Account Management (IAM)
RADIUS attributes
FortiToken physical device and FortiToken Mobile
FortiAuthenticator and FortiTokens
Monitoring FortiTokens
FortiToken device maintenance
FortiToken Mobile licenses
Portals
Portals
Policies
Captive portal policies
Self-service portal policies
Access points
FortiWLC Pinholes
Replacement messages
Smart Connect profiles
Remote authentication servers
General
LDAP
RADIUS
OAUTH
SAML
RADIUS service
Clients
Policies
Certificates
Services
Custom dictionaries
TACACS+ service
Creating policies
Adding clients
Creating authorization rules
Assigning authorization rules
LDAP service
General
Directory tree overview
Creating the directory tree
Configuring a FortiGate unit for FortiAuthenticator LDAP
OAuth Service
General
Policies
Relying Party
SAML IdP
General
Replacement messages
Service providers
FortiAuthenticator agents
FortiAuthenticator Agent for Microsoft Windows
FortiAuthenticator Agent for Outlook Web Access
Legacy self-service portal
General
Self-registration
Token self-provisioning
Device self-enrollment
Port-based network access control
Extensible Authentication Protocol
Non-compliant devices
Fortinet Single Sign-On
General settings
Portal services
SAML authentication
Windows event log sources
RADIUS accounting sources
Syslog sources
Fine-grained controls
SSO users and groups
Domain groupings
FortiGate filtering
IP filtering rules
Tiered architecture
FortiClient SSO Mobility Agent
RADIUS Single Sign-On
RADIUS accounting proxy
Monitoring
SSO
Domains
SSO sessions
Windows event log sources
FortiGates
DC/TS agents
NTLM statistics
Authentication
Locked-out users
RADIUS sessions
Windows AD
Windows device logins
Learned RADIUS users
SAML IdP sessions
Certificate management
Policies
End entities
Certificate authorities
Local CAs
Certificate revocations lists
Trusted CAs
SCEP
General
Enrollment requests
Logging
Log access
Log configuration
Audit reports
Troubleshooting
Troubleshooting
Debug logs
Troubleshooting SMTP server tests
LDAP filter syntax
Change Log
Home
FortiAuthenticator 6.4.4
Administration Guide
Administration Guide
What's new in FortiAuthenticator
FortiAuthenticator 6.4.4
FortiAuthenticator 6.4.3
FortiAuthenticator 6.4.2
FortiAuthenticator 6.4.1
FortiAuthenticator 6.4.0
Introduction
Before you begin
How this guide is organized
Registering your Fortinet product
Setup
Initial setup
FortiAuthenticator-VM setup on VMware
Administrative access
Adding FortiAuthenticator to your network
Maintenance
Backing up the configuration
Upgrading the firmware
Licensing
Swapping hard disks
Platform migration
CLI commands
Troubleshooting
FortiAuthenticator settings
FortiGate settings
System
Dashboard
Customizing the dashboard
System information widget
System resources widget
Authentication activity widget
User inventory widget
License information widget
Disk monitor widget
Top user lockouts widget
User lookup
Power supply monitor widget
Network
Interfaces
DNS
Static routing
Zero trust tunnels
Configuring a zero trust tunnel example
Packet capture
Administration
System access
High availability
Firmware upgrade
Configuring auto-backup
SNMP
Features
Licensing
FortiGuard
FortiNACs
FTP servers
Admin profiles
NetHSMs
Replacement messages
Messaging
SMTP servers
Email services
SMS gateways
Authentication
What to configure
Password-based authentication
Two-factor authentication
Two-factor token and password concatenation
Authentication servers
RADIUS
Built-in LDAP
Remote LDAP
Authentication methods
Machine authentication
User account policies
General
PCI DSS 3.2 two-factor authentication
Lockouts
Passwords
Custom user fields
Tokens
User management
Administrators
Local users
Remote users
Remote user sync rules
Guest users
User groups
Usage profile
Realms
FortiTokens
MAC devices
Identity and Account Management (IAM)
RADIUS attributes
FortiToken physical device and FortiToken Mobile
FortiAuthenticator and FortiTokens
Monitoring FortiTokens
FortiToken device maintenance
FortiToken Mobile licenses
Portals
Portals
Policies
Captive portal policies
Self-service portal policies
Access points
FortiWLC Pinholes
Replacement messages
Smart Connect profiles
Remote authentication servers
General
LDAP
RADIUS
OAUTH
SAML
RADIUS service
Clients
Policies
Certificates
Services
Custom dictionaries
TACACS+ service
Creating policies
Adding clients
Creating authorization rules
Assigning authorization rules
LDAP service
General
Directory tree overview
Creating the directory tree
Configuring a FortiGate unit for FortiAuthenticator LDAP
OAuth Service
General
Policies
Relying Party
SAML IdP
General
Replacement messages
Service providers
FortiAuthenticator agents
FortiAuthenticator Agent for Microsoft Windows
FortiAuthenticator Agent for Outlook Web Access
Legacy self-service portal
General
Self-registration
Token self-provisioning
Device self-enrollment
Port-based network access control
Extensible Authentication Protocol
Non-compliant devices
Fortinet Single Sign-On
General settings
Portal services
SAML authentication
Windows event log sources
RADIUS accounting sources
Syslog sources
Fine-grained controls
SSO users and groups
Domain groupings
FortiGate filtering
IP filtering rules
Tiered architecture
FortiClient SSO Mobility Agent
RADIUS Single Sign-On
RADIUS accounting proxy
Monitoring
SSO
Domains
SSO sessions
Windows event log sources
FortiGates
DC/TS agents
NTLM statistics
Authentication
Locked-out users
RADIUS sessions
Windows AD
Windows device logins
Learned RADIUS users
SAML IdP sessions
Certificate management
Policies
End entities
Certificate authorities
Local CAs
Certificate revocations lists
Trusted CAs
SCEP
General
Enrollment requests
Logging
Log access
Log configuration
Audit reports
Troubleshooting
Troubleshooting
Debug logs
Troubleshooting SMTP server tests
LDAP filter syntax
Change Log
6.4.4
6.5.3
6.5.2
6.5.1
6.5.0
6.4.8
6.4.7
6.4.6
6.4.5
6.4.4
6.4.3
6.4.2
6.4.1
6.4.0
6.3.4
6.3.3
6.3.2
6.3.1
6.3.0
6.2.2
6.2.1
6.2.0
6.1.3
6.1.2
6.1.1
6.1.0
6.0.8
6.0.7
6.0.6
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.5.0
5.4.0
5.3.0
5.2.0
5.1.0
5.0.0
4.3.0
4.2.1
4.2.0
Download PDF
Copy Doc ID
9189677a-bf71-11ec-9fd1-fa163e15d75b:512318
Copy Link
Maintenance
System
maintenance tasks include:
Backing up the configuration
Upgrading the firmware
Licensing
Swapping hard disks
Platform migration
Previous
Next
Maintenance
System
maintenance tasks include:
Backing up the configuration
Upgrading the firmware
Licensing
Swapping hard disks
Platform migration
Previous
Next
Link
PDF
TOC